Weaknesses of type CWE-532

858 results

Exposição de Informações Sensíveis em Logs

Aplicações registram dados confidenciais (senhas, tokens, chaves de API, números de cartão) em arquivos de log que ficam acessíveis a usuários não autorizados ou são capturados em backups, análises e monitoramento. Esse registro desprotegido transforma logs em porta de entrada para comprometimento de credenciais e dados pessoais.

Example

Um sistema web que loga tentativas de autenticação incluindo username e senha em texto plano em /var/log/app.log, ou uma API que registra o token JWT completo em logs estruturados que acabam replicados em servidores de análise compartilhados com múltiplos times.

How to mitigate

Implemente um filtro de sanitização que mascara ou remove dados sensíveis antes de gravar em logs (senhas, tokens, PII). Restrinja acesso a arquivos de log apenas a usuários autorizados e implemente rotação de logs com criptografia de arquivos históricos. Revise periodicamente o que está sendo logado em produção.

CVE-2025-8663HIGHInsertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain CredentialsEPSS 0.3%CVE-2024-29958HIGHEncryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node.EPSS 0.3%CVE-2026-29184LOW@backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction BypassEPSS 0.3%CVE-2021-3425—A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfileEPSS 0.3%CVE-2019-11271MEDIUMBosh Deployment logs leak sensitive informationEPSS 0.3%CVE-2025-30205HIGHkanidm-provision leaks provisioned admin credentials into the system logEPSS 0.3%CVE-2024-24939LOWIn JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possibleEPSS 0.3%CVE-2022-43673MEDIUMWire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of EPSS 0.3%CVE-2025-7426CRITICALMINOVA TTA Information Disclosure and Credential ExposureEPSS 0.3%CVE-2025-7371MEDIUMOkta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows aEPSS 0.3%CVE-2026-20205HIGHSensitive Information Disclosure in ''_internal'' index in Splunk MCP Server appEPSS 0.3%CVE-2024-32051MEDIUMInsertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a networkEPSS 0.3%CVE-2024-34715LOWPartial Password Exposure Vulnerability in Fides Webserver LogsEPSS 0.3%CVE-2024-44239MEDIUMAn information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPEPSS 0.3%CVE-2024-8775MEDIUMAnsible-core: exposure of sensitive information in ansible vault files due to improper loggingEPSS 0.3%CVE-2025-12940LOWCredentials recorded in logs in NETGEAR WAX610 and WAX610YEPSS 0.3%CVE-2023-46742MEDIUMCubeFS leaks users key in logsEPSS 0.3%CVE-2024-58269MEDIUMRancher exposes sensitive information through audit logsEPSS 0.3%CVE-2024-3744MEDIUMKubernetes azure-file-csi-driver in versions before 1.29.4 and 1.30.1 discloses service account tokens in logsEPSS 0.3%CVE-2025-64650MEDIUMIBM Storage Defender - Resiliency Service Information DisclosureEPSS 0.3%